Parties
This Data Processing Agreement (“Agreement”) forms part of the Solheim Terms of Service (the “Principal Agreement”) between Solheim OÜ, a private limited company registered in Estonia under registry code 17596617, Tornimäe tn 5, 10145 Tallinn, Estonia (the “Data Processor” or “Solheim”), and the customer using the Services (the “Company”, meaning any business or organisation using the Services, whatever its legal form) (together the “Parties”).
It applies wherever the Company’s use of the Services involves the Processing of Personal Data subject to Data Protection Laws, and it prevails over the Principal Agreement on data protection matters. No signature is required: the Company accepts this Agreement by creating an account, placing an order or using the Services. Terms not defined here have the meaning given in the Principal Agreement.
Whereas
(A) The Company acts as a Data Controller, or as a Data Processor on behalf of a third-party Controller. Where the Company acts as a Processor, Solheim acts as a Subprocessor in respect of the relevant Personal Data, and references in this Agreement to the Company’s instructions mean the instructions of that Controller as communicated by the Company.
(B) The Company wishes to use Solheim’s LLM inference services, which involve the processing of personal data contained in prompts, files and other inputs submitted by the Company and its end users.
(C) The Parties seek to implement a data processing agreement that complies with Regulation (EU) 2016/679 (the “GDPR”), in particular Article 28.
(D) The Parties wish to lay down their rights and obligations.
IT IS AGREED AS FOLLOWS:
1. Definitions and interpretation
1.1 Unless otherwise defined, capitalised terms have the following meanings:
-
“Agreement” means this Data Processing Agreement and all Annexes.
-
“Company Personal Data” means any Personal Data Processed by a Contracted Processor on behalf of the Company under or in connection with the Principal Agreement, including personal data contained in Customer Content.
-
“Contracted Processor” means Solheim or a Subprocessor.
-
“Customer Content” means prompts, system prompts, uploaded files, context, and model outputs submitted to or generated by the Services for the Company.
-
“Data Protection Laws” means the GDPR, the Estonian Personal Data Protection Act, any other EU or Member State data protection law applicable to the Processing, and, where the Company or the relevant Controller is subject to them, the UK GDPR and the Data Protection Act 2018.
-
“EEA” means the European Economic Area.
-
“Services” means the LLM inference services, API gateway and related hosting that Solheim provides under the Principal Agreement.
-
“Subprocessor” means any person appointed by or on behalf of Solheim to Process Company Personal Data in connection with this Agreement.
1.2 The terms “Commission”, “Controller”, “Data Subject”, “Member State”, “Personal Data”, “Personal Data Breach”, “Processing” and “Supervisory Authority” have the same meaning as in the GDPR, and their cognate terms are construed accordingly.
1.3 If this Agreement conflicts with the Principal Agreement on data protection matters, this Agreement prevails.
1.4 This Agreement takes effect on the earlier of the Company’s acceptance under section 12.7 or Solheim’s confirmation of the Company’s first order.
2. Processing of Company Personal Data
2.1 Solheim shall:
-
comply with all applicable Data Protection Laws in the Processing of Company Personal Data; and
-
not Process Company Personal Data other than on the Company’s documented instructions, unless required by EU or Member State law. In that case Solheim shall inform the Company of that legal requirement before Processing, unless that law prohibits it.
2.2 The Company instructs Solheim to Process Company Personal Data solely to provide the Services, as described in Annex I. The Principal Agreement, this Agreement and the Company’s use and configuration of the Services constitute the Company’s complete instructions.
2.3 Solheim shall not use Customer Content to train, fine-tune or evaluate any model, and shall not sell or share Customer Content with third parties except Subprocessors under section 5.
2.4 Solheim shall immediately inform the Company if, in its opinion, an instruction infringes Data Protection Laws.
2.5 Roles. Where the Company is a Controller, the Company is the Controller and Solheim the Processor. Where the Company Processes Personal Data on behalf of a third-party Controller, the Company is the Processor and Solheim the Subprocessor. Where the Company acts as a Processor, it warrants that it is authorised by the relevant Controller to appoint Solheim, to give the instructions in this Agreement and to authorise the Subprocessors in Annex III.
2.6 Company obligations. The Company is solely responsible for the accuracy, quality and legality of Company Personal Data and for the means by which it obtained that data. The Company shall ensure that it, or the relevant Controller, has given all notices, obtained all consents and established all other lawful bases required for Solheim and its Subprocessors to Process Company Personal Data under this Agreement.
2.7 Prohibited content. The Company shall not submit to the Services any Personal Data that it is not lawfully entitled to submit, and shall not by act or omission cause Solheim to breach Data Protection Laws through Processing carried out in accordance with this Agreement.
3. Processor personnel
Solheim shall take reasonable steps to ensure the reliability of any employee, agent or contractor who may access Company Personal Data. Access is limited to those individuals who need it for the Services, and each is subject to a confidentiality undertaking or statutory obligation of confidentiality.
4. Security
4.1 Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of Processing, as well as the risk to the rights and freedoms of natural persons, Solheim shall implement appropriate technical and organisational measures to ensure a level of security appropriate to that risk, including, as appropriate, the measures in Article 32(1) GDPR.
4.2 In assessing the appropriate level of security, Solheim shall take account in particular of the risks presented by a Personal Data Breach.
4.3 The measures in place at the date of this Agreement are listed in Annex II. Solheim may update them, provided the overall level of security is not reduced.
5. Subprocessing
5.1 The Company grants Solheim general written authorisation to engage the Subprocessors listed in Annex III.
5.2 Solheim shall notify the Company by email at least 30 days before adding or replacing a Subprocessor. The Company may object on reasonable data protection grounds within that period. If the Parties cannot resolve the objection, the Company may terminate the affected Services and receive a pro-rata refund of prepaid fees.
5.3 Solheim shall impose on each Subprocessor, by written contract, data protection obligations no less protective than those in this Agreement. Solheim remains fully liable to the Company for each Subprocessor’s performance.
6. Data subject rights
6.1 Taking into account the nature of the Processing, Solheim shall assist the Company by appropriate technical and organisational measures, insofar as possible, to fulfil the Company’s obligation to respond to requests to exercise Data Subject rights under Chapter III GDPR.
6.2 Solheim shall:
-
promptly notify the Company if it receives a request from a Data Subject relating to Company Personal Data;
-
not respond to that request except on the Company’s documented instructions or as required by applicable law; and
-
if it receives a request from a public authority, law enforcement agency or court for Company Personal Data, notify the Company unless legally prohibited from doing so, seek to redirect the requesting authority to the Company, and challenge any such request that appears unlawful or overbroad.
7. Personal Data Breach
7.1 Solheim shall notify the Company without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Company Personal Data. The notice shall include the information the Company needs to meet its obligations under Articles 33 and 34 GDPR, as far as then available. Solheim shall provide further information in phases as it becomes available, without undue further delay.
7.2 Solheim shall cooperate with the Company and take reasonable steps to assist in the investigation, mitigation and remediation of each Personal Data Breach.
7.3 Each Party bears its own costs of investigation, remediation and mitigation of a Personal Data Breach, and the costs of the other Party, to the extent the breach was caused by that Party.
7.4 Each Party bears any fines, penalties, damages or similar amounts imposed by a supervisory authority, regulator or court of competent jurisdiction to the extent they arise from that Party’s breach of its obligations under this Agreement.
8. Data Protection Impact Assessment and prior consultation
Solheim shall provide reasonable assistance to the Company with any data protection impact assessments and prior consultations with Supervisory Authorities that the Company reasonably considers required under Articles 35 or 36 GDPR. This assistance is limited to the Processing of Company Personal Data by Contracted Processors.
9. Deletion or return of Company Personal Data
9.1 Subject to section 9.2, Solheim shall, within 30 days after the end of the Services, at the Company’s choice return or delete all Company Personal Data and delete existing copies.
9.2 Solheim may retain Company Personal Data only to the extent required by EU or Member State law, and only for the period so required. Solheim shall keep it confidential and Process it only for the purpose requiring its retention.
9.3 Solheim shall provide written confirmation of deletion on request.
9.4 The Company acknowledges that Solheim does not store, log or otherwise retain Customer Content. Customer Content is processed only transiently in ephemeral memory, to the extent necessary to provide the Services, and is not persisted to any storage system. The return or recovery of Customer Content by Solheim is therefore technically impossible, and sections 9.1 to 9.3 apply to account, billing and request metadata.
10. Audit rights
10.1 Solheim shall make available to the Company on request the information necessary to demonstrate compliance with this Agreement, including its then-current security documentation and any third-party certifications or audit reports it holds. Where that information reasonably answers the Company’s request, it satisfies this section.
10.2 Where the information under section 10.1 is not sufficient, Solheim shall allow for and contribute to audits, including inspections, by the Company or an auditor mandated by the Company, in relation to the Processing of Company Personal Data by Contracted Processors, on the following terms:
-
no more than once per calendar year, except following a Personal Data Breach affecting Company Personal Data or on the instruction of a Supervisory Authority;
-
on at least 60 days’ prior written notice;
-
during Solheim’s business hours, without disrupting its operations and without access to other customers’ data or premises;
-
the Parties shall agree in advance on the date, scope, duration and the security and confidentiality controls applying to the audit;
-
Solheim may require the Company and any mandated auditor to sign a non-disclosure agreement beforehand, and the auditor must not be a competitor of Solheim; and
-
the Company bears its own and the auditor’s costs, and Solheim’s reasonable costs of assisting beyond the information under section 10.1.
10.3 The Company’s information and audit rights arise under section 10.1 only to the extent the Principal Agreement does not otherwise give it information and audit rights meeting the requirements of Data Protection Laws.
11. Data transfer
11.1 Solheim Processes Customer Content only in data centres located within the EU/EEA. Solheim shall not transfer, or authorise the transfer of, Company Personal Data to a country outside the EU/EEA except where that country is subject to an adequacy decision under Article 45 GDPR or a transfer mechanism under Chapter V GDPR is in place. By accepting this Agreement the Company authorises the Subprocessors, processing locations and transfer safeguards set out in Annex III; changes are notified under section 5.2 and the Company’s objection right in that section applies.
11.2 Where Company Personal Data is transferred from the EEA to a country without an adequacy decision, the transfer is governed by the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), which are incorporated into this Agreement by reference. By accepting this Agreement the Parties accept the Standard Contractual Clauses, which are treated as executed and completed when this Agreement takes effect. The elections and annex information required by the Clauses are set out in Annex IV.
11.3 Where Personal Data is transferred from the United Kingdom, the Parties adopt the UK International Data Transfer Addendum (version B1.0) to the Standard Contractual Clauses, on the terms set out in Annex IV.
11.4 In the event of a conflict between this Agreement and the Standard Contractual Clauses, the Standard Contractual Clauses prevail.
12. General terms
12.1 Confidentiality. Each Party shall keep confidential this Agreement and all information it receives from the other Party about the other Party’s business in connection with this Agreement. It shall not use or disclose that information without the other Party’s prior written consent, except where:
-
disclosure is required by law; or
-
the information is already in the public domain.
12.2 Notices. All notices under this Agreement shall be in writing and sent by email. Solheim shall notify the Company at the email address registered to its account; the Company shall notify Solheim at privacy@solheim.ai.
12.3 Term. This Agreement remains in force for as long as Solheim Processes Company Personal Data under the Principal Agreement.
12.4 Liability.
(a) Each Party’s liability under this Agreement is subject to, and capped in accordance with, the limitations of liability in the Principal Agreement, save where Data Protection Laws do not permit such limitation.
(b) Nothing in this Agreement limits either Party’s liability for fines or penalties imposed directly on it by a competent supervisory authority arising from that Party’s own breach of applicable Data Protection Laws.
12.5 Compliance with applicable laws. Solheim shall Process Company Personal Data in accordance with this Agreement and the Data Protection Laws applicable to its role as Processor. Solheim is not responsible or liable for compliance with Data Protection Laws or sector-specific requirements that apply to the Company by virtue of its own business or industry.
12.6 Language. This Agreement is concluded in English. Where it is translated, the English version prevails in the event of any discrepancy.
12.7 Acceptance and counterparts. The Company’s creation of an account, placing of an order or use of the Services constitutes its acceptance of this Agreement. Where the Company’s own compliance requires a signed standalone copy, Solheim will execute one on request; the terms are those in force at the date of that request.
12.8 Changes. Solheim may update this Agreement where required by Data Protection Laws or by a change to the Services, provided the update does not reduce the protection of Company Personal Data. Solheim shall notify the Company by email at least 30 days before an update takes effect, and the Company may terminate the affected Services within that period if it does not accept the update.
13. Governing law and jurisdiction
13.1 This Agreement is governed by the laws of the Republic of Estonia.
13.2 Any dispute arising in connection with this Agreement, which the Parties cannot resolve amicably, shall be submitted to the exclusive jurisdiction of Harju County Court (Harju Maakohus), Tallinn.
Annex I – Details of Processing
| Item | Detail |
|---|---|
| Subject matter | Provision of LLM inference via the Solheim API gateway |
| Duration | Term of the Principal Agreement, plus the deletion period in section 9 |
| Nature | Receiving, queueing, running model inference on, and returning Customer Content; account administration and usage metering |
| Purpose | Generating model outputs requested by the Company; billing by concurrency slot; abuse prevention and security |
| Data subjects | Company staff and end users of the Company’s applications; any individuals referenced in Customer Content |
| Categories of data | Any personal data the Company chooses to include in Customer Content; account contact details; API key identifiers; IP addresses and request metadata (timestamps, token counts, model, latency) |
| Special categories | Not intended. The Company shall not submit Article 9 or 10 data unless agreed in writing and supported by additional safeguards |
| Retention | Customer Content processed only transiently in ephemeral memory for the duration of the request and not persisted to any storage system; request metadata kept for 90 days; billing records as required by Estonian accounting law |
Annex II – Technical and organisational measures
Solheim’s current security documentation is published at solheim.ai/security and may be updated from time to time, provided the overall level of protection is not reduced. The measures include:
- Encryption: TLS 1.2+ for all traffic in transit; encryption at rest for stored data and backups.
- Access control: administrative access restricted to authorised personnel using SSH keys and multi-factor authentication, on a least-privilege basis.
- Tenancy and isolation: requests from several customers may be served by the same model instance. Customer Content is isolated logically: each request is authenticated against the Company’s API key, held only for the duration of that request, and no customer can access another customer’s requests, queue entries or outputs.
- Logging and retention: prompts and outputs are excluded from application logs; logs hold request metadata only, retained as set out in Annex I.
- Availability and incident response: infrastructure-as-code redeployment, monitoring and alerting on gateway and GPU hosts, and a documented breach procedure supporting notification within the period in section 7.
Annex III – Authorised Subprocessors
The current list is published at solheim.ai/subprocessors and this Annex reflects it as at the date of this Agreement. Changes are notified under section 5.2.
| Subprocessor | Service | Processing location | Transfer safeguard |
|---|---|---|---|
| Verda | GPU compute for inference | Finland, EU | EU/EEA, none needed |
| Scaleway SAS | API gateway, Redis and web UI hosting | France, EU | EU/EEA, none needed |
| Stripe | Payment processing | EU / US | Standard Contractual Clauses and EU-US Data Privacy Framework |
| Mollie B.V. | Payment processing. Authorised but not yet in use; Solheim will publish the date it goes live | Netherlands, EU | EU/EEA, none needed |
| Lettermint | Transactional email delivery | Netherlands, EU | EU/EEA, none needed |
Annex IV – Standard Contractual Clauses: elections and annex information
These elections apply to the Standard Contractual Clauses incorporated under section 11.2.
Module. Module Two (Controller to Processor) applies where the Company is a Controller. Module Three (Processor to Processor) applies where the Company acts as a Processor on behalf of a third-party Controller.
Clause 7 (docking clause). Not applicable.
Clause 9(a) (subprocessors). Option 2, general written authorisation. The notice period is 30 days, as set out in section 5.2.
Clause 11(a) (redress). The optional independent dispute resolution mechanism is not selected.
Clause 13 and Annex I.C (competent supervisory authority). The Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), unless the data exporter is established in another Member State, in which case that Member State’s supervisory authority applies.
Clause 17 (governing law). Option 1. The law of Estonia.
Clause 18(b) (forum). The courts of Estonia.
Annex I.A (list of parties). Data exporter: the Company. Data importer: Solheim OÜ, registry code 17596617, Tornimäe tn 5, 10145 Tallinn, Estonia.
Annex I.B (description of transfer). The categories of data subjects, categories of personal data, special categories, nature, purpose and retention period are those set out in Annex I. Transfers take place on a continuous basis for the term of the Principal Agreement.
Annex II (technical and organisational measures). As set out in Annex II of this Agreement.
Annex III (list of subprocessors). As set out in Annex III of this Agreement.
United Kingdom. For transfers from the United Kingdom, the Parties comply with Part 2 (Mandatory Clauses) of the UK International Data Transfer Addendum, version B1.0, laid before Parliament on 2 February 2022. Part 1 of the Addendum is completed with the information in this Annex IV. References to the GDPR are read as references to the UK GDPR, references to Member States as references to the United Kingdom, the governing law is the law of England and Wales and the forum is the courts of England and Wales. Either Party may end the Addendum as set out in Section 19 of the Mandatory Clauses.